Top

Summary

Prevalence: High

Name: Worm.Win32.VB.bi

Type: Worm

How it spreads: Email Attachments

Affected operating: Windows

Aliases: Nyxem.D, Kama Sutra,W32.Blackmal.E@mm,CME-24 ,WORM

Date of surface: 17 January 2006

Description

This is a mass mailing worm that spreads through file sharing networks and lowers security settings on the compromised computers.<BR><BR>It arrives as an Email-Attachments with the following extensions in Zipped format:<BR><BR>Attachments00.HQX<BR>WinZip.BHX<BR>Video_part.mim<BR>eBook.Uu<BR>Attachments001.BHX<BR>3.92315089702606E02.UUE<BR>Original Message.B64<BR>Word_Document.uu<BR>Sex.min <BR>WinZip Quick Pick.exe<BR>HRM_AF.exe<BR><BR>Subject lines may be any of the following:<BR>Kama Sutra pics<BR>Miss Lebanon 2006<BR>School girl fantasies gone bad<BR>The Best Videoclip Ever<BR>Re: Sex Video<BR>Fw:Sexy<BR>eBook.pdf<BR>Re:<BR>Word File<BR>Hello<BR>Fwd:Crazy illegal Sex!<BR>the file<BR>Fw:SeX.mpg<BR><BR>It copies itself with some of the following filenames:<BR><BR><Windows>\Rundll16.exe<BR><System>\scanregw.exe<BR><System>\Winzip.exe<BR><System>\Update.exe<BR><System>\WinZip_Tmp.exe<BR><System>\New WinZip File.exe<BR>movies.exe<BR>Zipped Files.exe<BR><BR><BR><BR><BR><BR> <BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR>

Recovery

<b>You have to remove the virus. You need to do one of the following things:</b><BR><BR>1) The latest virus vaccine update of eScan removes the worm from your system. Ensure that Internet access for your system is running. Right click on <img src="../images/e.gif" align="absmiddle"> and click <b> Download eScan update</b>. The latest updates are downloaded,your system is scanned and the worm is removed.<BR><BR><b>OR</b><BR><BR>2) Download the free MicroWorld Anti Virus Toolkit</a> (MWAV Tool Kit). The tool checks your machine for viruses. If any illegal dialers or sniffer tools have been installed they are detected. <BR><BR><BR><a name="mwav"><b>MWAV Tool Kit</b></a><BR>(Download the free MicroWorld Anti Virus Toolkit that detects viruses in system registry and running processes)<BR><BR><a href="ftp://ftp.microworldsystems.com/download/tools/mwav.exe">Link 1</a><BR><a href="ftp://update.mailscan.info/download/tools/mwav.exe">Link 2</a><BR><a href="http://www.mwti.net/download/tools/mwav.exe">Link 3</a><BR><BR><b>eScan Internet Security Suite (ISS)</b></a><BR>(Download MicroWorld`s eScan that detects viruses in system registry,running processes and has a real time monitor)<BR><BR><a href="ftp://ftp.microworldsystems.com/download/escan/es2k3e/iwn2k3e.exe">Link 1</a><BR><a href="ftp://ftp.das.com/mwti/download/escan/iwn2k3e.exe">Link 2</a><BR><a href="ftp://mwti.matrix.lv/download/escan/iwn2k3e.exe">Link 3</a><BR><a href="ftp://update.mailscan.info/download/escan/iwn2k3e.exe">Link 4</a><BR><a href="ftp://abundis.net/download/escan/iwn2k3e.exe">Link 5</a><BR><a href="http://www.mwti.net/download/escan/es2k3e/iwn2k3e.exe">Link 6</a><BR>

Advanced

This is a mass mailing worm that spreads through file sharing networks and lowers security settings on the compromised computers.<BR><BR>Also there is a new variant Email-Worm.Win32.Nyxem.e that has shown similar behavior as Email.Worm.Win32.VB.bi.<BR><BR>It arrives as an Email-Attachments with the following extensions in Zipped format:<BR><BR>Attachments00.HQX<BR>WinZip.BHX<BR>Video_part.mim<BR>eBook.Uu<BR>Attachments001.BHX<BR>3.92315089702606E02.UUE<BR>Original Message.B64<BR>Word_Document.uu<BR>Sex.min <BR>WinZip Quick Pick.exe<BR>HRM_AF.exe<BR><BR>Subject lines may be any of the following:<BR><BR>Fw:Sexy<BR>eBook.pdf<BR>Re:<BR>Word File<BR>Hello<BR>Fwd:Crazy illegal Sex!<BR>the file<BR>Fw:SeX.mpg<BR><BR>It copies itself with some of the following filenames:<BR><BR><Windows>\Rundll16.exe<BR><System>\scanregw.exe<BR><System>\Winzip.exe<BR><System>\Update.exe<BR><System>\WinZip_Tmp.exe<BR><System>\New WinZip File.exe<BR>movies.exe<BR>Zipped Files.exe